DocumentCode :
1908129
Title :
Capability based Secure Access Control to Networked Storage Devices
Author :
Factor, Michael ; Naor, D. ; Rom, E. ; Satran, J.
Author_Institution :
IBM Haifa Lab., Haifa
fYear :
2007
fDate :
24-27 Sept. 2007
Firstpage :
114
Lastpage :
128
Abstract :
Today, access control security for storage area networks (zoning and masking) is implemented by mechanisms that are inherently insecure, and are tied to the physical network components. However, what we want to secure is at a higher logical level independent of the transport network; raising security to a logical level simplifies management, provides a more natural fit to a virtualized infrastructure, and enables a finer grained access control. In this paper, we describe the problems with existing access control security solutions, and present our approach which leverages the OSD (Object-based Storage Device) security model to provide a logical, cryptographically secured, in-band access control for today´s existing devices. We then show how this model can easily be integrated into existing systems and demonstrate that this in-band security mechanism has negligible performance impact while simplifying management, providing a clean match to compute virtualization and enabling fine grained access control.
Keywords :
authorisation; storage area networks; capability based secure access control; networked storage device; object-based storage device security model; storage area network; Access control; Access protocols; Cryptography; Data security; Encapsulation; Image storage; Read only memory; Secure storage; Storage area networks; Virtual machining; access control; capability-based security protocol.; networked; security; storage; virtualization;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Mass Storage Systems and Technologies, 2007. MSST 2007. 24th IEEE Conference on
Conference_Location :
San Diego, CA
Print_ISBN :
978-0-7695-3025-3
Type :
conf
DOI :
10.1109/MSST.2007.4367968
Filename :
4367968
Link To Document :
بازگشت